SUSPICIOUS — ab79affe31326c3a59b74a3aa4863207251deb7279f02d6177cf3a84031b2162.exe
SUSPICIOUS — ab79affe31326c3a59b74a3aa4863207251deb7279f02d6177cf3a84031b2162.exe is a pe sample analyzed by MalwareAnalyzer by Cyble with a suspicious verdict (35/100). 5 of 52 detection engines flagged it.
Identification
- SHA-256:
ab79affe31326c3a59b74a3aa4863207251deb7279f02d6177cf3a84031b2162 - SHA-1:
bf8e7181755cabed4958cd9508acfd9403fa6f0d - MD5:
1434d6d230e62adfc6f2a4d6f31d465c - imphash:
6ed4f5f04d62b18d96b26d6db7c18840 - ssdeep:
49152:GGt/n9evLbq8ylGYw7lTMwJeq7pAJEkujD0L5QBKcoMQsTmLkJdZ/vVdPuAx+0D:GGlSLbOhg9kGCGjD0FQ80MkrFuw+0A - TLSH:
T1FF6033BA6B0D0E73D782C12C4D721CFE8F60DA126C6A48BE50576B615F6B11345FB1A0 - Submitted as: ab79affe31326c3a59b74a3aa4863207251deb7279f02d6177cf3a84031b2162.exe
- File type: pe · Size: 3594240 bytes
- Verdict: suspicious (35/100)
Source: MalwareBazaar · first seen 2026-08-01T00:00:00.000Z · SHA-256 verified
Detections (5 of 52 engines)
- MalwareAnalyser heuristics (entropy/packer): UPX
- Detect It Easy (packer/type): DIE:UPX
- Microsoft Defender: Trojan:Win32/Malgent
- Emsisoft (Emergency Kit): Gen:Variant.Draftor.3954
- Kaspersky (KVRT): Trojan-PSW.Win64.Salat.pbu
Why this verdict
The suspicious score of 35/100 is the fusion of 2 weighted signals:
- Detect It Easy (packer/type) flagged DIE:UPX (rule
DIE:UPX) - engine signal, weight 0.35, confidence 0.70 - Packing/obfuscation: UPX, high-entropy-sections:UPX1 - static signal, weight 0.25, confidence 0.55
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
Embedded domains
- c.tw
File paths
- E:\InJ
- K:\=~
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report